I have a VPC with RDS available in a private subnet. I can connect to this from an EC2 box from within the subnet. However, my Lambdas cannot connect!
Please could you look at the following configuration and spot my mistake?
Lambda config:
$ aws lambda get-function-configuration --function-name test
"FunctionName": "test",
"Role": "arn:aws:iam::xxxx:role/lambda_role",
"VpcConfig": {
"SubnetIds": [
"SecurityGroupIds": [
"VpcId": "vpc-0704ca4d3f652fe9e"
"RevisionId": "e55b6fa2-998a-4b18-a620-69a218882b4e"
Execution role:
$ aws list-attached-role-policies --role-name lambda_role
"AttachedPolicies": [
"PolicyName": "AWSLambdaVPCAccessExecutionRole",
"PolicyArn": "arn:aws:iam::aws:policy/service-role/AWSLambdaVPCAccessExecutionRole"
$ aws ec2 describe-vpcs --vpc-ids vpc-0704ca4d3f652fe9e
"Vpcs": [
"CidrBlock": "",
"DhcpOptionsId": "dopt-7764271f",
"State": "available",
"VpcId": "vpc-0704ca4d3f652fe9e",
"InstanceTenancy": "default",
"CidrBlockAssociationSet": [
"AssociationId": "vpc-cidr-assoc-0c110a5fa85eb8883",
"CidrBlock": "",
"CidrBlockState": {
"State": "associated"
"IsDefault": false,
"Tags": []
Security Group:
$ aws ec2 describe-security-groups --group-ids sg-018da51b77f57eabf
"SecurityGroups": [
"Description": "Security group for Lambdas",
"GroupName": "lambda-sg",
"IpPermissions": [],
"OwnerId": "xxxxx",
"GroupId": "sg-018da51b77f57eabf",
"IpPermissionsEgress": [
"FromPort": 0,
"IpProtocol": "tcp",
"IpRanges": [
"CidrIp": ""
"Ipv6Ranges": [],
"PrefixListIds": [],
"ToPort": 65535,
"UserIdGroupPairs": []
"VpcId": "vpc-0704ca4d3f652fe9e"
RDS security group (specifies both public and private subnets):
$ aws ec2 describe-security-groups --group-ids sg-0fbf7205b5d5fa98c
"SecurityGroups": [
"Description": "Security group for RDS instance",
"GroupName": "rds-sg",
"IpPermissions": [
"FromPort": 3306,
"IpProtocol": "tcp",
"IpRanges": [
"CidrIp": ""
"CidrIp": ""
"CidrIp": ""
"CidrIp": ""
"Ipv6Ranges": [],
"PrefixListIds": [],
"ToPort": 3306,
"UserIdGroupPairs": []
"OwnerId": "xxxxxx",
"GroupId": "sg-0fbf7205b5d5fa98c",
"IpPermissionsEgress": [],
"VpcId": "vpc-0704ca4d3f652fe9e"